PT-2024-1246 · Microsoft+6 · Identity+6

Morgan Brown

·

Published

2024-01-09

·

Updated

2024-12-13

·

CVE-2024-21319

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Identity versions prior to 5.7.0 Microsoft Identity versions prior to 6.34.0 Microsoft Identity versions prior to 7.1.2
Description The issue is related to incorrect clearing or release of resources in the Microsoft Identity library for the .NET platform. An attacker could exploit this by crafting a malicious JSON Web Encryption (JWE) token with a high compression ratio, leading to excessive memory allocation and processing time during decompression, causing a denial-of-service (DoS) condition. The attacker must have access to the public encrypt key registered with the IDP (Entra ID) for successful exploitation.
Recommendations For versions prior to 5.7.0, update to version 5.7.0 or higher. For versions prior to 6.34.0, update to version 6.34.0 or higher. For versions prior to 7.1.2, update to version 7.1.2 or higher.

Fix

DoS

Improper Resource Release

RCE

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0150
ALSA-2024:0151
ALSA-2024:0152
ALSA-2024:0156
ALSA-2024:0157
ALSA-2024:0158
ALT-PU-2024-13117
ALT-PU-2024-13118
ALT-PU-2024-16742
ALT-PU-2024-16744
ALT-PU-2024-16792
ALT-PU-2024-16794
ALT-PU-2024-16796
ALT-PU-2024-16939
ALT-PU-2024-2554
ALT-PU-2024-2556
ALT-PU-2024-2557
ALT-PU-2024-5998
ALT-PU-2024-6034
BDU:2024-00642
BIT-DOTNET-2024-21319
BIT-DOTNET-SDK-2024-21319
CESA-2024_0150
CESA-2024_0157
CESA-2024_0158
CVE-2024-21319
GHSA-59J7-GHRG-FJ52
GHSA-8G9C-28FC-MCX2
RHSA-2024:0150
RHSA-2024:0151
RHSA-2024:0152
RHSA-2024:0156
RHSA-2024:0157
RHSA-2024:0158
RHSA-2024:0255
RHSA-2024_0150
RHSA-2024_0151
RHSA-2024_0152
RHSA-2024_0156
RHSA-2024_0157
RHSA-2024_0158
RLSA-2024:0157
RLSA-2024:0158
USN-6578-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Identity
Red Hat
Ubuntu